Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

341–350 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#341

Earlier quoted context omitted.

It looks to me like there is an advantageous business relationship between Beeper and their customers. As a general rule, Apple is free to change their programs and how they work. However, I think there’s a plausible argument for tortious interference here if the sole purpose was to prevent interoperability.

Not sure why this is getting downvoted – IAAL and this is definitely something worth considering. This particular type of law varies from state to state, and can be quite broad. I've talked with other lawyers about it in the past, and my understanding is that it's frequently asserted when companies make counterclaims in business litigation. That doesn't mean it's a sure winner, just that it's a live question until mo…

I think most or all states recognize that the defendant’s actions must not be justified or privileged. It’s hard to imagine how Beeper would meet that element on these facts.

Re: Apple cuts off Beeper Mini's access

#342
post #261

As someone in tech, I think it's awesome they were able to find a way into iMessage. As an iPhone user, I hate the idea that spammers can now use iMessage, and I'm glad the service was taken down. Both things can be true at once.

Spam is not really an issue. For me, it just goes to the "Unknown Senders" tab. No notification, so I am not bothered. Occasionally check it if I am expecting a message from a random number.

Not really an issue for you. There are plenty of people for whom this is not viable.

Re: Apple cuts off Beeper Mini's access

#343
post #300

Earlier quoted context omitted.

Sure, that's fair. But if he knows that, why spend the time to build this app in the first place? Is it a marketing play? It did buy them a whole lot of attention.

Besides the obvious attention play, he might be going for an acquisition play... "Why bother writing our own iMessage for Android when we can just buy this little company that's already done it?" There's obvious issues with that plan, but that doesn't keep delusional founders from being delusional.

Apple chose not to support Android on purpose. They know iMessage exclusivity drives hardware sales. The emails have come out proving as much.

It's the same reason they dragged their feet supporting RCS, until regulatory pressure started mounting.

Re: Apple cuts off Beeper Mini's access

#344
post #142

Earlier quoted context omitted.

I find this a bit confusing though. It seems like this was an inevitable outcome, but what do they gain from this technical investment aside from exposure. Their website doesn't steer users to anything other than the now cut-off Beeper mini?

Exposure is something. The fact the developer had the chops to do this is now on the public record. That could be very valuable for getting a job or a college scholarship (since they’re in HS).

I did something similar, built an entire app around an undocumented developer api, got a lot of users and then ended up in a good enough position to find out there was a "hidden" official api for sale and it opened a lot of doors as well even to the same site had gotten it from. For someone as young as that with nothing but time, I'm sure they knew the outcome and it blowing up was probably more than they could ask for.

Re: Apple cuts off Beeper Mini's access

#345
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

Not sure that's worth much congratulation. Is there anyone that didn't think the exact same thing as soon as they saw the story?

A good chunk of the posters on the release thread seemed to think otherwise.

Re: Apple cuts off Beeper Mini's access

#346

I'm guessing the binary they use from Apple (IMDAppleServices) to generate part of the registration information probably adds metadata to the "validation blob" that gets sent to apple when registering beeper mini as an iMessage device. If the metadata includes the OS version, Apple probably blacklisted any new devices registered in the past few days with validation blobs generated from that binary. (The binary was so…

My suspicion is this is going to be a cat-mouse situation for a while.

Apple would've found some easy way to identify these users and Beeper will likely release a patch to fix it.

Re: Apple cuts off Beeper Mini's access

#347

Earlier quoted context omitted.

I think they don't like being spit on and excluded by iphone users. Iphone users don't like when there are android users in group chats. The reason the iphone users don't like it is because Apple specifically and artificially makes the experience annoying and shitty in several different ways, for the iphone users not just for the Android users.

Good grief! No one is spitting on people with Android phones. If you really feel this way you need to put your screen down and spend time talking to people in real life. No one is persecuting you.

No one is literally spitting, but Apple intentionally creates enough friction that Android users really do regularly get excluded from group chats in the US where iMessage is the convention for group chats.

Re: Apple cuts off Beeper Mini's access

#348

Earlier quoted context omitted.

If signal would officially allow third party clients, non-phone-number-bound users and maybe federation that'd be great. It does not.

As very recently made evident, Signal spends a significant amount of money maintaining their phone-number-bound infrastructure, with an entirely plausible, reasonable, user-focused reason for doing so. As a Signal user, and donator, I’m 100% okay with the trade-off they’ve made, and would hate to see it reversed just to appeal to some nerdy pipe-dream for how services should work.

> As very recently made evident, Signal spends a significant amount of money maintaining their phone-number-bound infrastructure, with an entirely plausible, reasonable, user-focused reason for doing so.

If there is some recent revelation that makes phone numbers all of a sudden a secure, portable and censorship-resistant identifier please link me that.

Until then I'd prefer to not have my private communication determined by telephone companies that often have not cared for either security, censorship or privacy. Regardless of signals e2e encryption having my access to the network determined by a telephone company is not the right way to go.

Re: Apple cuts off Beeper Mini's access

#349

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

They had a cloud of Apple devices that they already used for their relay service, and could easily generate keys using several devices. From my understanding, the best vector for Apple was to actually block their "BPN", the push server.

Re: Apple cuts off Beeper Mini's access

#350

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

And Apple didn't even need to block any device identifiers, just the IPs Beeper Mini was using to connect to the APN service.

This could have been blocked in minutes. The delay was likely to get approval from Legal.

Post reply on HN